Back to skill

Security audit

Chroma Vector Db

Security checks for vulnerabilities and agentic risk

Overview

This Chroma database skill needs review because its main instructions include unrelated finance backtesting behavior and setup steps.

Do not install this as a Chroma-only helper unless the publisher replaces the ZVT/finance content or republishes it accurately as a finance skill. If you review it manually, block automatic package installation, command execution, credential use, local finance data setup, and .skill persistence until the artifacts describe one coherent purpose.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file is a clear skill-identity mismatch: the package metadata says this is a Chroma vector database skill, but the human summary instructs the agent to act as a ZVT quant-strategy/backtesting assistant. This can cause the agent to present unsupported capabilities, auto-fetch unrelated finance-specific constraints, and generate financial code or advice under the false cover of a database skill, which is especially risky in autonomous or tool-using environments.

Description-Behavior Mismatch

Critical
Confidence
99% confidence
Finding
The file is presented as a Chroma vector database skill, but its operational and user-facing content is overwhelmingly for ZVT quant trading/backtesting. This kind of capability mismatch is dangerous because users or hosts may invoke/install a finance execution workflow under the false belief that they are enabling a vector DB helper, defeating user consent and security review boundaries.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The install recipes and preconditions execute and validate ZVT finance tooling even though the skill claims to be for Chroma. This can cause unintended package installation and execution of unrelated code paths, expanding attack surface and enabling a bait-and-switch from harmless-seeming vector DB operations to market-data/backtesting workflows.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The declared architecture and validators implement a trading/backtest pipeline with strategy validation gates rather than vector database behavior. This is dangerous because downstream automation may trust these sections to understand runtime behavior, yet they conceal materially different execution semantics including data collection, trading logic, and result validation.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The user-facing documentation explicitly promises ZVT quant-strategy help while the enclosing skill is labeled as Chroma vector DB. Misleading human-facing text increases the chance that users approve or invoke a skill without understanding its real behavior, which is especially dangerous when the hidden behavior involves code execution and data handling outside the advertised scope.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The execute trigger uses broad matching of positive terms plus generic action verbs, which increases the chance of accidental invocation. In the context of a mislabeled skill that may install or run unrelated tooling, overbroad activation is more dangerous because it can trigger unintended execution paths from ordinary conversation.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The trigger phrase "question answering" is generic and likely to match many unrelated user requests. Because this skill already exhibits domain confusion, broad triggering raises the risk of invoking the wrong capability and steering users into unrelated package installation or execution flows.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The term "persistence" is too generic to safely activate a specific skill path. In this file, ambiguous routing is especially risky because the skill content mixes Chroma and ZVT behaviors, so a generic trigger could send a user into an unrelated operational flow.

Vague Triggers

Medium
Confidence
72% confidence
Finding
The term "image" is overly broad and can match many ordinary requests unrelated to multimodal vector retrieval. In a skill with mismatched declared and actual behaviors, such ambiguity materially increases the chance of false activation and user confusion.

Vague Triggers

Medium
Confidence
75% confidence
Finding
The trigger phrase "deployment" is broad and commonly appears in many technical conversations. Since this skill contains operational instructions and package installation behavior, accidental activation could lead users into infrastructure guidance or execution steps they did not intend to request.

Vague Triggers

Medium
Confidence
74% confidence
Finding
The trigger phrase "task" is highly ambiguous and can appear in ordinary conversation with no relation to Chroma Cloud tasks. Given the file's broader evidence of confused or deceptive scope, generic activation terms make unintended invocation substantially more likely.

Static analysis

No suspicious patterns detected.